SigmaShake Guardrails for Grok Bot
SigmaShake Guardrails evaluates AI tool calls against SSG rules (ALLOW/DENY/ASK/FORCE/LOG/SHADOW) and provides honest-agent safeguards — integration-dependent guardrails, not a sandbox.
Transport selection (local vs hosted)
Use one or both. Prefer local when a reachable machine has ssg installed; keep hosted as the remote fallback (additive — do not remove hosted when enabling local).
| Preference | When | How |
|---|---|---|
| Local stdio (preferred when available) | Grok Bot / Cursor can spawn on a machine with ssg (your Mac, machine-targeted tools, ssg init --client=grok-bot) | ssg mcp-server --client=grok-bot via ~/.cursor/mcp.json server ssg-governance-grok-bot, or plugin pack mcp.local.json → sigmashake-guardrails-local |
| Hosted Streamable HTTP (default marketplace) | No local ssg, or remote-only connector on the bot computer | Plugin mcp.json → POST https://mcp.sigmashake.com/mcp with Authorization: Bearer <license-key> |
Client name: always --client=grok-bot (adapter id). Do not use --client=grok here — that is the separate Grok CLI adapter.
If both servers are registered, call eval tools on the local server first (ssg-governance-grok-bot / sigmashake-guardrails-local); fall back to hosted sigmashake-guardrails when local tools are missing or unreachable.
Install (hosted — marketplace default)
Landing page: grok.sigmashake.com
- Subscribe at sigmashake.com/pricing and copy your license key.
- Install the SigmaShake Guardrails plugin from the Cursor Marketplace (submit path: cursor.com/marketplace/publish) or from the public pack github.com/sigmashakeinc/sigmashake-guardrails.
- Set
SSG_LICENSE_KEYunder Plugins → Configure. - Confirm health:
GET https://mcp.sigmashake.com/health.
Install (local stdio — additive)
When ssg is on the machine Grok Bot can reach:
ssg init --client=grok-bot
That writes/merges ~/.cursor/mcp.json (and project .cursor/mcp.json) with:
{
"mcpServers": {
"ssg-governance-grok-bot": {
"command": "ssg",
"args": ["mcp-server", "--client=grok-bot"],
"env": { "SSG_CLIENT": "grok-bot" }
}
}
}
Or copy the plugin pack's mcp.local.json entry (sigmashake-guardrails-local) into Cursor MCP settings / Grok Bot Add MCP server (stdio):
- command:
ssg(or absolute path, e.g./opt/homebrew/bin/ssg/~/.local/bin/ssg) - args:
mcp-server,--client=grok-bot - env:
SSG_CLIENT=grok-bot
Leave the hosted plugin entry in place for fallback.
MCP endpoints
| Transport | URL / command |
|---|---|
Local stdio (when ssg reachable) | ssg mcp-server --client=grok-bot |
| Streamable HTTP (hosted) | POST https://mcp.sigmashake.com/mcp |
| Legacy SSE | GET https://mcp.sigmashake.com/sse then POST /message |
| Health (hosted) | GET https://mcp.sigmashake.com/health |
Hosted auth: Authorization: Bearer <license-key>.
Decisions
ALLOW, DENY, ASK, FORCE, LOG, SHADOW. If eval is unavailable, fail closed on destructive, secret, irreversible, or rule-mutation actions.
Never create, edit, delete, or sync live SSG rules (*.rules, .sigmashake/rules/, ssg_write_rule, ssg rule sync, ssg hub pull into a live rules dir). Draft rule text in chat only.
These are honest-agent safeguards, not a kernel sandbox. Do not invent SHAKEDOWN numbers.
See also: MCP Server, Client Adapters, Agent Install Guide.